Principal Network Engineer – Global Infrastructure & Cyber Resilience
Commvault (NASDAQ: CVLT) is the gold standard in cyber resilience, empowering customers to uncover, take action, and rapidly recover from cyberattacks while keeping data safe and businesses resilient. The company’s AI-powered platform combines data protection, security, intelligence, and recovery across any workload or cloud at the lowest TCO. For over 25 years, more than 100,000 organizations and a vast partner ecosystem have relied on Commvault to reduce risks, improve governance, and do more with data.
About the role
As a Principal Network Engineer at Commvault, you will act as a Player-Coach—a technical heavyweight who architects a global network while personally building and troubleshooting it. This role is defined by deep execution: you will own the full lifecycle of our global connectivity fabric, from whiteboarding a Zero Trust framework to hands-on configuration and resolving complex multi-cloud routing issues. If you are a high-level architect who has moved away from the CLI, this is not the role for you; we need a leader who stays "close to the packets" while guiding long-term technical strategy.
Responsibilities
- Hands-On Technical Leadership & Execution
- Build & Deploy: Lead the hands-on implementation of global SD-WAN and Cloud nodes, ensuring a flawless transition from design to production.
- Deep-Dive Troubleshooting: Act as the ultimate technical escalation point, diving into logs, PCAPs, and routing tables to identify and fix root causes.
- Network-as-Code: Develop and maintain Terraform and Ansible playbooks to automate the global environment, driving execution rather than just suggesting it.
- Multi-Cloud & SD-WAN Sovereignty
- GCP & Azure Execution: Physically build and manage transit gateways, VPC/VNet peering, and Cloud Interconnects for our multi-cloud ecosystem.
- SD-WAN Mastery: Configure Prisma Access and Next-Generation Firewalls (NGFWs), owning the policy engine to bake security into every route and interface.
- Zero Trust Integration: Execute micro-segmentation and identity-based access controls across our hybrid footprint, moving beyond buzzwords to real implementation.
- Security & Edge Engineering
- Zscaler and Firewall Expert: Serve as the Subject Matter Expert (SME) for NGFWs, Zscaler Private Access (ZPA), and Zero Trust Network Access (ZTNA), owning global policy sets, SSL decryption strategies, and threat prevention profiles.
- Hybrid Connectivity: Manage complex Site-to-Site VPNs, GRE tunnels, and high-speed interconnects linking global data centers with public cloud regions.
- Mentorship, Leadership & Executive Presence
- Strategic Influence: Partner with the CISO and Director of Infrastructure to align networking goals with broader business initiatives.
- Technical Mentorship: Lead and upskill a global team of senior and mid-level engineers through architectural reviews and setting documentation and code-based infrastructure standards.
- Vendor Management: Lead technical evaluations and Quarterly Business Reviews (QBRs) with key partners (Google, Microsoft, Palo Alto) to leverage the latest features and optimal pricing.
- Lead by Example: Demonstrate best practices in configuration, documentation, and operational discipline to set the technical standard for the engineering team.
- Executive Communication: Translate complex technical challenges and execution hurdles into concise executive summaries, providing clear paths for risk mitigation.
- Automation & Excellence
- Infrastructure as Code (IaC): Champion a "Network-as-Code" mindset using Terraform, Ansible, or Python to automate repetitive tasks and ensure 100% configuration consistency.
- Operational Resilience: Own Tier-4 escalations for complex network outages and lead Root Cause Analysis (RCA) sessions to translate technical failures into actionable business improvements.
Requirements
- 12+ years in Network Engineering, with a career path demonstrating hands-on expertise.
- Preferably located in New Jersey to manage hardware in the corporate data center.
- Proven ability to build, operate, and troubleshoot complex environments across Palo Alto (PCNSE level), GCP, and Azure.
- Direct experience deploying Zscaler SD-WAN and implementing ZTNA frameworks in a global enterprise.
- Expert-level mastery of BGP, EVPN/VXLAN, and stateful firewalling.
- High proficiency in Python or Terraform for infrastructure deployment.
- Ability to command a room of executives while being the most technical person on a bridge call.
- Exceptional written and verbal communication skills, capable of explaining technical concepts to both executives and engineers.
Preferred Qualifications
- Zscaler certifications: ZTDA or ZTDE.
- Cloud certifications: Google Professional Cloud Network Engineer or Azure Network Engineer Associate (AZ-700).
- CCIE (Route/Switch or Security) is highly valued but not required if equivalent experience is demonstrated.
Benefits
- Continuous professional development, product training, and career pathing.
- Inclusive company culture with opportunities to join Employee Groups.
- Generous benefits supporting health, financial security, and work-life balance.
- Employee stock purchase plan (ESPP).
Pay
Pay Range: $93,500—$182,850 USD. The specific salary offered will be determined based on your unique qualifications, including relevant experience, skills, and the value you bring to the role.